Hi Brock,
On 13.12.2012 16:28, Brock Tice wrote:
Is there something I am missing?
Look closely at the first "Received" header:
received:_from_[209.188.113.101]_by_web184904.mail.gq1.yahoo.com_via_HTTP;_Tue,_11_Dec_2012_03:54:56_PST
This means the spam was sent via Yahoo, and got delivered there from your exit via HTTP (Webmail).
Is there anything else I should do to prevent this in the future?
There's not much you can do about this, unless you want to systematically block all webmail services. :-(
Could there be some way that a Tor user could locally send mail using my server?
It's always good to take a look at the Received headers to rule out that someone has managed to break into your server.